Skip to content

Conversation

@nalind
Copy link
Member

@nalind nalind commented Dec 4, 2025

Ignore me!

TomSweeneyRedHat and others added 8 commits November 28, 2025 15:44
Bump runc to v1.2.9 to fix CVE-2025-52881.  This also
fixes CVE-2025-31133 and CVE-2025-52565.

Partially fixes: https://issues.redhat.com/browse/OCPBUGS-64913, https://issues.redhat.com/browse/OCPBUGS-64911
once merged into Podman.

runc v1.2.9 also fixes a couple of regressions that were in
the original CVE 1.2.8 patch.

Signed-off-by: tomsweeneyredhat <[email protected]>
The latest runc requires Go 1.22.  Bump int in the Makefile to that
version.

Signed-off-by: tomsweeneyredhat <[email protected]>
These functions were removed in github.com/opencontainers/selinux
v1.12.0.

Signed-off-by: tomsweeneyredhat <[email protected]>
Bumping golang.org/x/tools to v0.26.0 per @nalind's
suggestion.

Signed-off-by: tomsweeneyredhat <[email protected]>
Apparently, per lint, the userns.RunningInUserNS() function
has moved from runc, to moby.  Update the library location.

Signed-off-by: tomsweeneyredhat <[email protected]>
Update references to specific versions of golang in the Makefile and the
Cirrus CI configuration to match go.mod, and add a check in the 'vendor'
target that CI runs that the image it's run inside is a close-enough
match to the version listed in go.mod.

Signed-off-by: Nalin Dahyabhai <[email protected]>
Stealing from @cevich's work in containers#6520.
In CI, the project and tests are compiled, so therefore require newer
CI/VM images with support for the newer golang requirements.

Signed-off-by: tomsweeneyredhat <[email protected]>
Update the version of ginkgo that we build for use by our e2e tests.

Signed-off-by: Nalin Dahyabhai <[email protected]>
@openshift-ci
Copy link
Contributor

openshift-ci bot commented Dec 4, 2025

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: nalind

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@packit-as-a-service
Copy link

Ephemeral COPR build failed. @containers/packit-build please check.

1 similar comment
@packit-as-a-service
Copy link

Ephemeral COPR build failed. @containers/packit-build please check.

nalind and others added 3 commits December 4, 2025 13:38
* bump golangci-lint to v1.60.3
* bump golang.org/x/tools to v0.26.0

Signed-off-by: Nalin Dahyabhai <[email protected]>
Ambient capabilities can't be raised without inheritable ones, and since we
don't raise inheritable, we should not raise ambient either.

This went unnoticed because of a bug in syndtr/gocapability which is
only fixed in its fork (see the next commit).

Amends commit e7e55c9.

Signed-off-by: Kir Kolyshkin <[email protected]>
@nalind nalind force-pushed the ci-1.37 branch 2 times, most recently from 7266bbf to 0b1ab09 Compare December 4, 2025 19:13
@nalind nalind force-pushed the ci-1.37 branch 2 times, most recently from 6eeb4ea to 601d8a0 Compare December 4, 2025 23:21
The version of containers/common we're currently using on this branch included a
bug which was later fixed by containers/common#2199.
If we get an update on its v0.60 branch which includes that fix, we can
drop this patch from this branch, but until then, work around the part
that breaks our tests.

Signed-off-by: Nalin Dahyabhai <[email protected]>
Run integration tests (both as root and rootless) with both crun and
runc on Fedora, to help ensure that we can use either.

Signed-off-by: Nalin Dahyabhai <[email protected]>
nalind and others added 2 commits December 5, 2025 16:26
Handle requested relabeling of bind mounts (i.e., the "z" and "Z" flags)
directly, instead of letting the runtime handle the relabeling.

Signed-off-by: Nalin Dahyabhai <[email protected]>
Bump Buildah to v1.37.7

Signed-off-by: tomsweeneyredhat <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants